Medical Practice Platform
The complete patient platform for an independent Florida medical practice — patient portal, staff console, practice AI assistant, EHR integration, and billing. Built, deployed, and security-tested end-to-end by one accountable architect.
Outcome
Live on AWS — patient portal, admin console, and database running on HIPAA-eligible infrastructure (App Runner, RDS, Cognito), replacing the enterprise-portal path entirely
- Projected ~90% lower hosting cost than enterprise HIPAA portal tiers
- Adversarially security-tested — three independent reviews including live penetration testing, with a hard gate: no real patient data until every critical item is fixed and re-verified
- Five products, one platform — messaging, scheduling, intake, billing, and a practice AI assistant that runs on practice-controlled infrastructure
- In final security verification before patient onboarding
The Problem
Independent practices are trapped between two bad options. Enterprise patient-portal vendors charge per provider, gate HIPAA behind expensive add-on tiers, and won't customize. Consumer-grade tools can't legally touch PHI at all — every hosting provider, database, and auth system in the PHI path needs a signed BAA. This practice needed patients to message the care team, book appointments, complete intake, exchange documents, and pay bills — and needed staff to run the entire operation from one console — without enterprise pricing and without surrendering their patient relationships to a portal vendor's ecosystem.
The Architecture
Built a patient portal with secure login and a full self-service experience (messaging, scheduling, digital intake, document exchange, online bill pay via Stripe); a staff and admin console with role-based access (patient/staff/provider/admin) covering patient management, billing and invoicing with payment tracking, a message center, and operational reporting; a practice AI assistant running on self-hosted models on practice-controlled infrastructure so clinical context never leaves the practice's environment; and EHR and office integration via FHIR connectivity to the practice's EHR plus Microsoft 365 calendar and document sync. All PHI lives in encrypted AWS RDS behind AWS Cognito identity; every component in the PHI path is BAA-eligible. Audit logging, MFA, session controls, and encrypted document storage are architecture, not add-ons.
The Solution
The security gate is how we ship healthcare software: before a single real patient record enters the system, the platform is put through adversarial review — independent security audits, live penetration testing against production, a consolidated remediation program, and full re-verification. The BAA is executed only when the safeguards it attests are demonstrably true in production, not before. If a current vendor can't describe their equivalent of this paragraph, that's worth a conversation.
Stack & Role
Sole Architect & Developer
May – September 2026
Interested in working together?
I bring the same depth of thinking to client projects as I do to my own work.
Get in touch →